Bug 2488431 (CVE-2026-44967) - CVE-2026-44967 opentelemetry-: opentelemetry-cpp: Denial of Service via unbounded HTTP response read
Summary: CVE-2026-44967 opentelemetry-: opentelemetry-cpp: Denial of Service via unbou...
Keywords:
Status: NEW
Alias: CVE-2026-44967
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-06-12 16:02 UTC by OSIDB Bzimport
Modified: 2026-08-31 10:43 UTC (History)
7 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-06-12 16:02:42 UTC
OpenTelemetry-cpp is the C++ implementation of OpenTelemetry. Prior to release 1.27.0, the OTLP HTTP exporters (traces/metrics/logs) read the full HTTP response into an in-memory vector of bytes without a size cap. This is exploitable for memory exhaustion when the configured collector endpoint is attacker-controlled (or a network attacker can MITM the exporter connection). This vulnerability is fixed in opentelemetry-cpp release 1.27.0.


Note You need to log in before you can comment on or make changes to this bug.